Files
server/opt/psa/admin/sbin/nginx_proxy
2026-01-07 20:52:11 +01:00

1697 lines
43 KiB
Bash
Executable File

#!/bin/bash
### Copyright 1999-2025. WebPros International GmbH. All rights reserved.
#
#
# Plesk script
#
#default values
product_default_conf()
{
PRODUCT_ROOT_D=/opt/psa
PRODUCT_RC_D=/etc/init.d
PRODUCT_ETC_D=/opt/psa/etc
PLESK_LIBEXEC_DIR=/usr/lib/plesk-9.0
HTTPD_VHOSTS_D=/var/www/vhosts
HTTPD_CONF_D=/etc/apache2
HTTPD_INCLUDE_D=/etc/apache2/conf-enabled
HTTPD_BIN=/usr/sbin/apache2
HTTPD_LOG_D=/var/log/apache2
HTTPD_SERVICE=apache2
QMAIL_ROOT_D=/var/qmail
PLESK_MAILNAMES_D=/var/qmail/mailnames
RBLSMTPD=/usr/sbin/rblsmtpd
NAMED_RUN_ROOT_D=/var/named/run-root
WEB_STAT=/usr/bin/webalizer
MYSQL_VAR_D=/var/lib/mysql
MYSQL_BIN_D=/usr/bin
MYSQL_SOCKET=/var/run/mysqld/mysqld.sock
PGSQL_DATA_D=/var/lib/postgresql/16/main
PGSQL_CONF_D=/etc/postgresql/16/main
PGSQL_BIN_D=/usr/lib/postgresql/16/bin
DUMP_D=/var/lib/psa/dumps
DUMP_TMP_D=/tmp
MAILMAN_ROOT_D=/usr/lib/mailman
MAILMAN_VAR_D=/var/lib/mailman
PYTHON_BIN=/usr/bin/python2
GPG_BIN=/usr/bin/gpg
TAR_BIN=/usr/lib/plesk-9.0/sw-tar
AWSTATS_ETC_D=/etc/awstats
AWSTATS_BIN_D=/usr/lib/cgi-bin
AWSTATS_TOOLS_D=/usr/share/awstats/tools
AWSTATS_DOC_D=/usr/share/awstats
OPENSSL_BIN=/usr/bin/openssl
LIB_SSL_PATH=/lib/libssl.so
LIB_CRYPTO_PATH=/lib/libcrypto.so
CLIENT_PHP_BIN=/opt/psa/bin/php-cli
SNI_SUPPORT=true
APS_DB_DRIVER_LIBRARY=/usr/lib/x86_64-linux-gnu/sw/libmysqlserver.so.2.0
SA_MAX_MAIL_SIZE=256000
}
### Copyright 1999-2025. WebPros International GmbH. All rights reserved.
set_apache_params()
{
apache_user="www-data"
apache_UID=80
apache_group="www-data"
apache_GID=80
apache_pid_file="$APACHE_ROOT/logs/httpd.pid"
apache_lock_file="$APACHE_ROOT/logs/httpd.lock"
product_lock_file="$HTTPD_CONF_D/cnf.lock"
apache_service_name="apache2"
apache_modules_d="/usr/lib/apache2/modules"
apache_service="$apache_service_name"
apache_httpd_conf="$HTTPD_CONF_D/apache2.conf"
apache_httpd_include="$HTTPD_INCLUDE_D/zz010_psa_httpd.conf"
APACHE_ROOT="/usr"
min_suexec_UID=10000
max_suexec_UID=16000
min_suexec_GID=$min_suexec_UID
max_suexec_GID=$max_suexec_UID
suexec_storage=/usr/lib/plesk-9.0/suexec
suexec=/usr/lib/apache2/suexec
suexec_dir="`dirname "$suexec"`"
suexec_file="`basename "$suexec"`"
rpm_httpd_bin=/usr/sbin/httpd
}
### Copyright 1999-2025. WebPros International GmbH. All rights reserved.
# mode: shell-script
# vim: ft=sh
module_exists()
{
local dir
[ -n "$1" ] || return 1
test -e "${HTTPD_CONF_D}/mods-available/$1.load" && return
if [ -n "${additional_apache_modules_d}" ]; then
for dir in $additional_apache_modules_d; do
if [ -f "${dir}/mod_$1.so" ] ; then return ; fi
if [ -n "$2" -a -f "${dir}/$2" ] ; then return ; fi
done
fi
return 1
}
# Run before it
# read_conf
# # set_common_params
# set_apache_params
add_apache_module()
{
local module_name="$1"
local module_soname="$2" # optional
local config="$3" # optional
if ! module_exists $module_name "$module_soname"; then
p_echo "Load file ${HTTPD_CONF_D}/mods-available/$module_name.load for a2enmod not found"
return 1
fi
if [ -x /usr/sbin/a2enmod ]; then
/usr/sbin/a2enmod $module_name >> $product_log
else
warn "a2enmod utilily not found! Module $module_name was NOT enabled."
fi
}
# Run before it
# read_conf
# # set_common_params
# set_apache_params
remove_apache_module()
{
local module_name="$1"
local module_soname="$2" # optional
local config="$3" # optional
if [ -x /usr/sbin/a2dismod ]; then
/usr/sbin/a2dismod -f $module_name
else
warn "a2dismod utilily not found! Module $module_name was NOT disabled."
fi
}
is_function()
{
local type_output=$(type -t "$1")
test "X${type_output}" = "Xfunction"
}
### Copyright 1999-2025. WebPros International GmbH. All rights reserved.
# echo message to product log and console (always visible)
pp_echo()
{
if [ -n "$product_log" ] ; then
echo "$@" >> "$product_log" 2>&1
fi
echo "$@" >&2
}
# echo message to product log, also to console in debug mode
p_echo()
{
if [ -n "$product_log" ] ; then
echo "$@" >> "$product_log" 2>&1
fi
if [ -n "$PLESK_INSTALLER_DEBUG" -o -n "$PLESK_INSTALLER_VERBOSE" -o -z "$product_log" ] ; then
echo "$@" >&2
fi
}
# same as p_echo, but without new line
pnnl_echo()
{
p_echo -n "$@"
}
int_err()
{
report_problem "internal" "Internal error: $@"
exit 1
}
p_see_product_log()
{
log_is_in_dev "${product_log}" || printf " (see log file: ${product_log})" >&2
}
die()
{
report_problem "fatal" "ERROR while trying to $@"
printf "Check the error reason" >&2
p_see_product_log
echo ", fix and try again" >&2
selinux_close
exit 1
}
warn()
{
local inten="$1"
if [ -n "$PLESK_INSTALLER_DEBUG" -o -n "$PLESK_INSTALLER_VERBOSE" ]; then
p_echo
p_echo "WARNING!"
pnnl_echo "Some problems are found during $inten"
p_see_product_log
p_echo
p_echo "Continue..."
p_echo
fi
report_problem "warning" "Warning: $inten"
}
echo_try()
{
msg="$*"
pnnl_echo " Trying to $msg... "
}
suc()
{
p_echo "done"
}
### Copyright 1999-2025. WebPros International GmbH. All rights reserved.
reexec_with_clean_env()
{
# Usage: call this function as 'reexec_with_clean_env "$@"' at the start of a script.
# Don't use with scripts that require sensitive environment variables.
# Don't put the call under any input/output redirection.
# Purpose: make sure the script is executed with a sane environment.
local lc="`get_default_locale`"
export LANG="$lc" LC_MESSAGES="$lc" LC_ALL="$lc"
export PATH=/sbin:/bin:/usr/sbin:/usr/bin:/usr/local/sbin:/usr/local/bin
umask 022
PLESK_SCRIPT_COMMAND_LINE="$0 $*"
[ -z "$PLESK_INSTALLER_ENV_CLEANED" ] || { unset PLESK_INSTALLER_ENV_CLEANED; return 0; }
[ -n "$BASH" ] || exec /bin/bash "$0" "$@"
# N.B.: the following code requires Bash. On Dash it would cause syntax error upon parse w/o eval.
eval '
local extra_vars=() # list of variables to preserve
for var in "${!PLESK_@}"; do # enumerate all PLESK_* variables
extra_vars+=("$var=${!var}")
done
extra_vars+=("PLESK_INSTALLER_ENV_CLEANED=1")
# Exec self with clean env except for extra_vars, shell opts, and arguments.
exec /usr/bin/env -i "${extra_vars[@]}" /bin/bash ${-:+-$-} "$0" "$@" || {
echo "Failed to reexec self ($0) with clean environment" >&2
exit 91 # Just some relatively unique error code
}
'
}
get_default_locale()
{
# Note that CentOS 7 typically doesn't have C.UTF-8
for lc in "C.UTF-8" "en_US.UTF-8" "C"; do
if [ -z "`LC_ALL=$lc locale 2>&1 >/dev/null`" ]; then
echo "$lc"
return 0
fi
done
echo "C"
}
# accumulates chown and chmod
set_ac()
{
local u_owner g_owner perms node
u_owner="$1"
g_owner="$2"
perms="$3"
node="$4"
# A very small optimization - replacing of two execs by one,
# it works only if the following conditions are observed:
# - u_owner is username (not UID);
# - g_owner is group (not GID);
# - perms is in octal mode.
# If some conditions aren't observed,
# optimization doesn't work,
# but it doesn't break function
[ "$(stat -c '%U:%G 0%a' $node)" != "$u_owner:$g_owner $perms" ] || return 0
chown $u_owner:$g_owner $node || die "chown $u_owner:$g_owner $node"
chmod $perms $node || die "chmod $perms $node"
}
detect_vz()
{
[ -z "$PLESK_VZ_RESULT" ] || return $PLESK_VZ_RESULT
PLESK_VZ_RESULT=1
PLESK_VZ=0
PLESK_VE_HW_NODE=0
PLESK_VZ_TYPE=
local issue_file="/etc/issue"
local vzcheck_file="/proc/self/status"
[ -f "$vzcheck_file" ] || return 1
local env_id=`sed -ne 's|^envID\:[[:space:]]*\([[:digit:]]\+\)$|\1|p' "$vzcheck_file"`
[ -n "$env_id" ] || return 1
if [ "$env_id" = "0" ]; then
# Either VZ/OpenVZ HW node or unjailed CloudLinux
PLESK_VE_HW_NODE=1
return 1
fi
if grep -q "CloudLinux" "$issue_file" >/dev/null 2>&1 ; then
return 1
fi
if [ -f "/proc/vz/veredir" ]; then
PLESK_VZ_TYPE="vz"
elif [ -d "/proc/vz" ]; then
PLESK_VZ_TYPE="openvz"
fi
PLESK_VZ=1
PLESK_VZ_RESULT=0
return 0
}
# detects lxc and docker containers
detect_lxc()
{
[ -z "$PLESK_LXC_RESULT" ] || return $PLESK_LXC_RESULT
PLESK_LXC_RESULT=1
PLESK_LXC=0
if { [ -f /proc/1/cgroup ] && grep -q 'docker\|lxc' /proc/1/cgroup; } || \
{ [ -f /proc/1/environ ] && cat /proc/1/environ | tr \\0 \\n | grep -q "container=lxc"; };
then
PLESK_LXC_RESULT=0
PLESK_LXC=1
fi
return "$PLESK_LXC_RESULT"
}
call_optional_function()
{
local type_output="`LC_ALL=C type \"$1\" 2>/dev/null | head -n 1`"
case "$type_output" in
*function)
"$@"
;;
*)
return 0
;;
esac
}
### the function similar to awk -F'$fs' 'print $N'
get_narg_fs()
{
local IFS="$2"
get_narg $3 $1
}
get_narg()
{
shift $1 2>/dev/null || return 0
echo $1
}
get_ini_conf_var()
{
local conf="$1"
local section="$2"
local param="$3"
[ -n "$conf" -a -n "$param" ] || die "get_ini_conf_var(): required parameters missing"
local section_empty=0
[ -n "$section" ] || section_empty=1
perl -n -e 'BEGIN { $insect='$section_empty' }
next if (/^\s*;/);
$insect=0 if (/^\s*\[.*\]/);
$insect=1 if (/^\s*\['$section'\]/);
$val = $2, $val =~ s/\s+$//, print $val . "\n"
if ($insect && /^\s*('$param')\s*=\s*([^;\n]*)(;.*)?$/);' $conf | head -n 1
}
### Copyright 1999-2025. WebPros International GmbH. All rights reserved.
#-*- vim:syntax=sh
product_log_name_ex()
{
local aux_descr="$1"
local action="${CUSTOM_LOG_ACTION_NAME-installation}"
if [ -n "$aux_descr" ]; then
aux_descr="_${aux_descr}"
fi
if [ -n "$CUSTOM_LOG_NAME" ]; then
echo "${CUSTOM_LOG_NAME}${action:+_$action}${aux_descr}.log"
else
get_product_versions
echo "plesk_${product_this_version}${action:+_$action}${aux_descr}.log"
fi
}
product_log_name()
{
product_log_name_ex
}
product_problems_log_name()
{
product_log_name_ex "problems"
}
problems_log_tail()
{
[ -f "$product_problems_log" ] || return 0
{
tac "$product_problems_log" | awk '/^START/ { exit } { print }' | tac
} 2>/dev/null
}
product_log_tail()
{
[ -f "$product_log" ] || return 0
{
tac "$product_log" | awk '/^START/ { exit } { print }' | tac
} 2>/dev/null
}
product_and_problems_log_tail()
{
product_log_tail
[ "$product_log" = "$product_problems_log" ] || problems_log_tail
}
cleanup_problems_log()
{
[ -f "$product_problems_log" ] || return 0
touch "$product_problems_log.tmp"
chmod 0600 "$product_problems_log.tmp"
awk 'BEGIN { st = "" }
/^START/ && (st ~ /^START/) { print st; }
/^START/ { st=$0; next }
/^STOP/ && (st ~ /^START/) { st=""; next }
(st != "") { print st; st="" }
{ print }
' "$product_problems_log" > "$product_problems_log.tmp" && \
mv -f "$product_problems_log.tmp" "$product_problems_log" || \
rm -f "$product_problems_log.tmp"
if [ ! -s "$product_problems_log" ]; then
rm -f "$product_problems_log"
fi
}
mktemp_log()
{
local logname="$1"
local dir="$2"
if [ "${logname:0:1}" != "/" ]; then
logname="$dir/$logname"
fi
dir="`dirname $logname`"
if [ ! -d "$dir" ]; then
mkdir -p "$dir" || { echo "Unable to create log directory : $dir"; exit 1; }
if [ "$EUID" -eq "0" ]; then
set_ac root root 0700 "$dir"
fi
fi
if [ "${logname%XXX}" != "$logname" ]; then
mktemp "$logname"
else
echo "$logname"
fi
}
log_is_in_dev()
{
test "${1:0:5}" = "/dev/"
}
start_writing_logfile()
{
local logfile="$1"
local title="$2"
! log_is_in_dev "$logfile" || return 0
echo "START $title" >> "$logfile" || { echo "Cannot write installation log $logfile" >&2; exit 1; }
[ "$EUID" -ne "0" ] || set_ac root root 0600 "$logfile"
}
log_start()
{
true product_log_name product_problems_log_name mktemp_log
local title="$1"
local custom_log="$2"
local custom_problems_log="$3"
local product_log_dir="/var/log/plesk/install"
product_log="$product_log_dir/`product_log_name`"
product_problems_log="$product_log_dir/`product_problems_log_name`"
problems_occured=0
# init product log
[ ! -n "$custom_log" ] || product_log="$custom_log"
product_log=`mktemp_log "$product_log" "$product_log_dir"`
# init problems log
if [ -n "$custom_problems_log" ]; then
product_problems_log=`mktemp_log "$custom_problems_log" "$product_log_dir"`
elif [ -n "$custom_log" ]; then
product_problems_log="$product_log"
else
product_problems_log=`mktemp_log "$product_problems_log" "$product_log_dir"`
fi
# write starting message into logs
start_writing_logfile "$product_log" "$title"
if [ "$product_log" != "$product_problems_log" ]; then
start_writing_logfile "$product_problems_log" "$title"
fi
is_function profiler_setup && profiler_setup "$title" || :
}
log_transaction_start()
{
LOG_TRANSACTION_TITLE="$1"
LOG_TRANSACTION_SUBJECT="$2"
local log_transaction_custom_logfile="$3"
local log_transaction_custom_problems_logfile="$4"
transaction_begin autocommit
log_start "$LOG_TRANSACTION_TITLE" "$log_transaction_custom_logfile" "$log_transaction_custom_problems_logfile"
transaction_add_commit_action "log_transaction_stop"
transaction_add_rollback_action "log_transaction_stop"
}
log_transaction_stop()
{
log_stop "$LOG_TRANSACTION_TITLE" "$LOG_TRANSACTION_SUBJECT"
}
log_stop()
{
local title="$1"
local subject="$2"
if [ "$product_log" = "$product_problems_log" ] || \
log_is_in_dev "$product_problems_log"; then
[ -e "$product_log" ] && echo "STOP $title" >>"$product_log"
is_function profiler_stop && profiler_stop || :
return
fi
if [ -z "$subject" ]; then
subject="[${title}]"
fi
# check if problems are non-empty, check for problems_occured
local status
local problem_lines="`problems_log_tail | wc -l`"
if [ "$problem_lines" -eq 0 ]; then
status="completed successfully"
else
if [ $problems_occured -ne 0 ]; then
status="failed"
else
status="completed with warnings"
fi
fi
if [ -e "$product_log" ]; then
p_echo
p_echo "**** $subject $status."
p_echo
fi
if [ "$problem_lines" -ne 0 ]; then
[ ! -e "$product_log" ] || problems_log_tail >>"$product_log" 2>&1
problems_log_tail
fi
[ ! -e "$product_log" ] || echo "STOP $title" >>"$product_log"
if [ $problems_occured -ne 0 ]; then
echo "STOP $title: PROBLEMS FOUND" >>"$product_problems_log"
else
[ ! -s "$product_problems_log" ] || echo "STOP $title: OK" >>"$product_problems_log"
fi
if [ "X${PLESK_INSTALLER_KEEP_PROBLEMS_LOG}" = "X" ]; then
cleanup_problems_log
fi
is_function profiler_stop && profiler_stop || :
}
### Copyright 1999-2025. WebPros International GmbH. All rights reserved.
construct_report_template()
{
local severity="${1:-error}"
local summary="$2"
local update_ticket="`get_update_ticket`"
set_error_report_source
set_error_report_component
set_error_report_params
set_error_report_environment
true construct_report_code construct_report_debug construct_report_message
cat <<-EOL
<?xml version="1.0" encoding="UTF-8" ?>
<error>
<source>$report_source</source>
<severity>$severity</severity>
<datetime>`date --iso-8601=seconds`</datetime>
<component>$report_component</component>
<summary><![CDATA[`echo "$summary" | sed -e 's/\]\]>/] ]>/g'`]]></summary>
<message encoding="base64">`construct_report_message | base64`</message>
<additional_info>
<component_params encoding="base64">$report_params</component_params>
<code encoding="base64">`construct_report_code | base64`</code>
<debug encoding="base64">`construct_report_debug | base64`</debug>
<environment encoding="base64">$report_environment</environment>
<update_ticket>$update_ticket</update_ticket>
</additional_info>
</error>
EOL
}
construct_report_code()
{
local call_level=${1:-5}
local func_level=$[call_level - 1]
local lineno_func=${BASH_LINENO[ $func_level ]}
local script_name=${BASH_SOURCE[ $[func_level + 1] ]}
echo "# Call of ${FUNCNAME[$func_level]}() from ${FUNCNAME[$[func_level + 1]]}() at `readlink -m $script_name`:${BASH_LINENO[$func_level]}"
head -n $[lineno_func + 4] "$script_name" 2>/dev/null | tail -n 8
}
construct_report_debug()
{
local call_level=${1:-5}
call_level=$[call_level-1]
# Generate calls stack trace.
for i in `seq $call_level ${#FUNCNAME[@]}`; do
[ "${FUNCNAME[$i]}" != "main" ] || break
local func_call="`sed -n -e "${BASH_LINENO[$i]}p" "${BASH_SOURCE[$[i+1]]}" 2>/dev/null |
sed -e 's/^[[:space:]]*//' -e 's/[[:space:]]*$//'`"
[ -n "$func_call" -a -z "${func_call##*${FUNCNAME[$i]}*}" ] || func_call="${FUNCNAME[$i]}"
echo "#$[i - $call_level] `readlink -m ${BASH_SOURCE[$[i+1]]}`(${BASH_LINENO[$i]}): $func_call"
done
}
construct_report_message()
{
product_and_problems_log_tail
echo ""
if [ -n "$report_context" ]; then
echo "Context: $report_context"
echo ""
fi
if [ -n "$RP_LOADED_PATCHES" ]; then
echo "Loaded runtime patches: $RP_LOADED_PATCHES"
echo ""
fi
}
# Construct report to send it to our errors tracker
construct_report()
{
local severity="${1:-error}"
local summary="$2"
[ -n "$summary" ] || int_err "Unable to send error report. Some parameters are not defined."
set_error_report_source
get_product_versions
construct_report_template "$severity" "$summary" \
| $PRODUCT_ROOT_D/admin/bin/send-error-report --version "$product_this_version" $report_source >/dev/null 2>&1
}
# Use this function to report failed actions.
# Typical report should contain
# - reason or problem description (example: file copying failed)
# - how to resolve or investigate problem (example: check file permissions, free disk space)
# - how to re-run action (example: perform specific command, restart bootstrapper script, run installation again)
report_problem()
{
local severity="${1:-error}"
# Get first string of error as a summary of report
shift
local summary="$1"
[ -n "$product_problems_log" ] || product_problems_log="/dev/stderr"
p_echo
if [ "0$problems_occured" -eq 0 ]; then
echo "***** $process problem report *****" >> "$product_problems_log" 2>&1
fi
for problem_message in "$@"; do
p_echo "$problem_message"
if [ "$product_log" != "$product_problems_log" ]; then
echo "$problem_message" >> "$product_problems_log" 2>&1
fi
done
p_echo
construct_report "$severity" "$summary"
[ -n "$PLESK_INSTALLER_DEBUG" -o -n "$PLESK_INSTALLER_VERBOSE" ] || \
product_log_tail
problems_occured=1
}
set_error_report_source()
{
[ -z "$1" ] || report_source="$1"
[ -n "$report_source" ] || {
if [ -n "$PACKAGE_ID" -o -n "$PACKAGE_ACTION" -o -n "$PACKAGE_NAME" -o -n "$PACKAGE_VERSION" ]; then
report_source="install"
else
report_source="backend"
fi
}
}
set_error_report_component()
{
local component="$1"
if [ "$report_source" = "install" ]; then
[ -n "$report_component" ] || report_component="$PACKAGE_ID"
return 0
fi
[ -z "$component" ] || report_component="$1"
[ -n "$report_component" ] || report_component="`basename $0`"
}
set_error_report_params()
{
if [ "$report_source" = "install" ]; then
[ -n "$report_params" ] || report_params="`echo "$PACKAGE_ACTION of $PACKAGE_NAME $PACKAGE_VERSION" | base64`"
return 0
fi
[ -z "$*" ] || report_params="`echo "$*" | base64`"
[ -n "$report_params" ] || report_params="`echo "$PLESK_SCRIPT_COMMAND_LINE" | base64`"
}
detect_virtualization()
{
detect_vz
detect_lxc
local is_docker="`[ -f "/.dockerenv" ] && echo yes || :`"
local systemd_detect_virt_ct="`/usr/bin/systemd-detect-virt -c 2>/dev/null | grep -v '^none$' || :`"
local systemd_detect_virt_vm="`/usr/bin/systemd-detect-virt -v 2>/dev/null | grep -v '^none$' || :`"
local virt_what="`/usr/sbin/virt-what 2>/dev/null | xargs || :`"
if [ -n "$is_docker" ]; then
echo "docker $virt_what"
elif [ "$PLESK_VZ" = "1" ]; then
echo "${PLESK_VZ_TYPE:-virtuozzo}"
elif [ "$PLESK_LXC" = "1" ]; then
echo "lxc $virt_what"
elif [ -n "$systemd_detect_virt_ct" ]; then
echo "$systemd_detect_virt_ct $systemd_detect_virt_vm"
elif [ -n "$virt_what" ]; then
echo "$virt_what"
elif [ -n "$systemd_detect_virt_vm" ]; then
echo "$systemd_detect_virt_vm"
fi
}
default_error_report_environment()
{
local virtualization="`detect_virtualization`"
if [ -n "$virtualization" ]; then
echo "virtualization: $virtualization"
fi
}
set_error_report_environment()
{
[ -z "$*" ] || report_environment="`echo "$*" | base64`"
[ -n "$report_environment" ] || report_environment="`default_error_report_environment | base64`"
}
get_update_ticket()
{
[ -r $PRODUCT_ROOT_D/var/update_ticket ] && cat $PRODUCT_ROOT_D/var/update_ticket | awk '{$1=$1};1'
}
### Copyright 1999-2025. WebPros International GmbH. All rights reserved.
#
# Support for runtime patching of shell scripts (including utilities and package scripts).
#
# --- Service functions ---
# Load and apply a patch in a relatively safe way
rp_safe_load_patch()
{
local patch_file="$1"
echo_try "load shell patch '$patch_file'"
/bin/sh -n "$RP_BASEDIR/$patch_file" &&
{
. "$RP_BASEDIR/$patch_file"
RP_LOADED_PATCHES="$RP_LOADED_PATCHES $patch_file"
} &&
suc
}
# Apply patches specific to the current context (e.g., depending on utility basename or package name)
# This is currently not implemented. This may be overriden by "spark".
rp_patch_runtime_context_specific()
{
:
}
# --- Main entry points ---
rp_patch_runtime()
{
# List of loaded patch files
RP_LOADED_PATCHES=
local RP_BASEDIR="$PRODUCT_BOOTSTRAPPER_DIR/rp"
[ -d "$RP_BASEDIR" ] || return 0
if [ -r "$RP_BASEDIR/spark" ]; then
rp_safe_load_patch "spark"
fi
call_optional_function rp_patch_runtime_context_specific "$@"
}
### Copyright 1999-2025. WebPros International GmbH. All rights reserved.
transaction_begin()
{
[ -n "$TRANSACTION_STARTED" ] && die "Another transaction in progress!"
TRANSACTION_STARTED="true"
TRANSACTION_ROLLBACK_FUNCS=
TRANSACTION_COMMIT_FUNCS=
local transaction_autocommit="$1"
if [ -n "$transaction_autocommit" ]; then
trap "transaction_commit_auto" EXIT
trap "transaction_rollback" HUP PIPE INT QUIT TERM
else
trap "transaction_rollback" HUP PIPE INT QUIT TERM EXIT
fi
}
transaction_rollback()
{
TRANSACTION_RETURN_CODE="${TRANSACTION_RETURN_CODE:-$?}"
[ -z "$TRANSACTION_STARTED" ] && die "Transaction is not started!"
# perform rollback actions
local f
for f in ${TRANSACTION_ROLLBACK_FUNCS}; do
"$f"
done
TRANSACTION_STARTED=
TRANSACTION_ROLLBACK_FUNCS=
TRANSACTION_COMMIT_FUNCS=
trap - HUP PIPE INT QUIT TERM EXIT
exit 1
}
transaction_commit()
{
TRANSACTION_RETURN_CODE="${TRANSACTION_RETURN_CODE:-$?}"
[ -z "$TRANSACTION_STARTED" ] && die "Transaction is not started!"
# perform commit actions
local f
for f in ${TRANSACTION_COMMIT_FUNCS}; do
"$f"
done
TRANSACTION_STARTED=
TRANSACTION_ROLLBACK_FUNCS=
TRANSACTION_COMMIT_FUNCS=
trap - HUP PIPE INT QUIT TERM EXIT
}
transaction_commit_auto()
{
TRANSACTION_RETURN_CODE="$?"
if [ "$TRANSACTION_RETURN_CODE" -eq 0 ]; then
transaction_commit "$@"
else
transaction_rollback "$@"
fi
}
transaction_add_rollback_action()
{
[ -z "$TRANSACTION_STARTED" ] && die "Transaction is not started!"
# LIFO rollback order
[ -z "$TRANSACTION_ROLLBACK_FUNCS" ] \
&& TRANSACTION_ROLLBACK_FUNCS="$1" \
|| TRANSACTION_ROLLBACK_FUNCS="$1 $TRANSACTION_ROLLBACK_FUNCS"
}
transaction_add_commit_action()
{
[ -z "$TRANSACTION_STARTED" ] && die "Transaction is not started!"
# FIFO commit order
[ -z "$TRANSACTION_COMMIT_FUNCS" ] \
&& TRANSACTION_COMMIT_FUNCS="$1" \
|| TRANSACTION_COMMIT_FUNCS="$TRANSACTION_COMMIT_FUNCS $1"
}
get_group_id()
{
local name="$1"
[ -n "$name" ] || int_err "Wrong value of argument 'name': $name"
getent group "$name" 2>/dev/null | awk -F':' '{print $3}'
}
del_user_from_group()
{
local user group inten existing newlist
test $# -eq 2 || die "user or group is not defined"
inten="remove user ${1} from group ${2}"
echo_try "$inten"
user=$1
group="`get_group_id $2`"
[ -n "$group" ] || die "$inten"
existing=`id -G "$user"`
newlist=`echo "$existing" | xargs -n1 | grep -E -v "^${group}$" | xargs`
if [ "X${existing}" = "X${newlist}" ]; then
p_echo "user ${user} is not in group ${group}"
return
fi;
newlist=`echo "${newlist}" | sed 's|[[:space:]]\+|,|g'`
usermod -G "$newlist" "$user" 2>>"$product_log" && suc || die "$inten"
}
add_user_to_group()
{
local user group existing newlist
user="$1"
group="$2"
if [ -z "`get_group_id $group`" ]; then
p_echo " Group '$group' not exists"
p_echo " It is necessary to add group '$group'"
err
fi
inten="add supplementary group '$group' for user '$user'"
echo_try "$inten"
existing=`id -Gn "$user"|sed 's|[[:space:]]\+|,|g'`
if
test "`id -gn "$user"`" = "$group" \
|| echo "$existing" | grep -q "\\<$group\\>"
then
p_echo " already there"
return
fi
if test -z "$existing"; then
newlist="$group"
else
newlist="$existing,$group"
fi
usermod -G "$newlist" "$user" 2>>"$product_log" && suc || die "$inten"
}
### Copyright 1999-2025. WebPros International GmbH. All rights reserved.
# vim:ft=sh
initial_conf()
{
PRODNAME="psa"
PRODUCT_NAME="psa"
product=${PRODNAME}
PRODUCT_FULL_NAME="Plesk"
product_etc="/etc/${PRODNAME}"
prod_conf_t="/etc/psa/psa.conf"
support_contact="https://support.plesk.com/"
conceived_os_vendor=Ubuntu
conceived_os_version="24.04"
clients_group="psacln"
clients_GID="10001"
services_group="psaserv"
services_GID="10003"
product_suff="saved_by_${product}".`date "+%m.%d;%H:%M"`
product_suffo="saved_by_${product}"
# plesk default password
PRODUCT_DEFAULT_PASSWORD="setup"
}
read_conf()
{
[ -n "$prod_conf_t" ] || prod_conf_t=/etc/psa/psa.conf
if [ -s $prod_conf_t ]; then
tmp_var=`perl -e 'undef $/; $_=<>; s/#.*$//gm;
s/^\s*(\S+)\s*/$1=/mg;
print' $prod_conf_t`
eval $tmp_var
else
if ! is_product_installation; then
p_echo "Unable to find product configuration file: $prod_conf_t. Default values will be used."
return 1
fi
fi
return 0
}
### Copyright 1999-2025. WebPros International GmbH. All rights reserved.
#-*- vim:ft=sh
register_service() {
[ -n "$1" ] || die "register_service: service name not specified"
local inten="register service $1"
echo_try "$inten"
{
# sysvinit tools will not be called on systemd OS'es
# since such OS'es are not explicitly supported
enable_respawn_service "$1.service"
# systemctl daemon-reload is performed implicitly unless --no-reload is passed
/bin/systemctl enable --quiet "$1.service"
local rs_db="$PRODUCT_ROOT_D/admin/sbin/register_service_db"
[ ! -x "$rs_db" ] || "$rs_db" -a "$@"
}
suc
}
unregister_service() {
[ -n "$1" ] || die "unregister_service: service name not specified"
local inten="unregister service $1"
echo_try $inten
{
local rs_db="$PRODUCT_ROOT_D/admin/sbin/register_service_db"
[ ! -x "$rs_db" ] || "$rs_db" -r "$1"
disable_respawn_service "$1.service"
# systemctl daemon-reload is performed implicitly unless --no-reload is passed
/bin/systemctl disable --quiet "$1.service"
# purge sysvinit symlinks from /etc/rc.d which might be created by systemd-sysv-install
# it spawns `update-rc.d defaults` or `chkconfig --add` if sysvinit script exists
/usr/sbin/update-rc.d -f "$1" remove 1>/dev/null 2>&1 || :
} >> $product_log 2>&1
suc
}
### Copyright 1999-2025. WebPros International GmbH. All rights reserved.
#-*- vim:ft=sh
enable_respawn_service()
{
grep_q_recursive() {
local val="$1"
local file="$2"
if [ -f "$file" ]; then
! grep -q "$val" "$file" || return 0
for f in `sed -n -e "s/^\.include\s//p" $file`; do
! grep_q_recursive "$val" "$f" || return 0
done
fi
return 1
}
[ -n "$1" ] || die "enable_respawn_service: service name not specified"
local inten="enable automatic respawn for service $1"
echo_try "$inten"
local service=$1
local main_unit=`systemctl show $service | sed -n -e "s/FragmentPath=//p"`
local respawn_unit="/lib/systemd/system/$service.d/respawn.conf"
local dropin_units=`systemctl show $service | sed -n -e "s/DropInPaths=//p" | sed "s|$respawn_unit||"`
local ini="/opt/psa/admin/conf/panel.ini"
local ini_section="systemd"
local respawn
[ ! -f "$ini" ] || respawn=`get_ini_conf_var "$ini" "$ini_section" respawn`
if [ -z "${respawn/on/}" ]; then
for unit in $main_unit $dropin_units; do
! grep_q_recursive "^Restart=" "$unit" || respawn="off"
! grep_q_recursive "^Type=oneshot" "$unit" || respawn="off"
done
fi
rm -f "$respawn_unit"
if [ -z "${respawn/on/}" ]; then
mkdir -p "$(dirname $respawn_unit)"
if [ -f "$ini" ]; then
local restart=` get_ini_conf_var "$ini" "$ini_section" Service.Restart`
local restartsec=` get_ini_conf_var "$ini" "$ini_section" Service.RestartSec`
fi
cat <<EOT > "$respawn_unit"
[Service]
Restart=${restart:-"on-failure"}
RestartSec=${restartsec:-"5"}
EOT
fi
suc
}
disable_respawn_service()
{
[ -n "$1" ] || die "disable_respawn_service: service name not specified"
local inten="disable automatic respawn for service $1"
echo_try "$inten"
local respawn_unit="/lib/systemd/system/$1.d/respawn.conf"
rm -f "$respawn_unit"
suc
}
### Copyright 1999-2025. WebPros International GmbH. All rights reserved.
# vim:ft=sh
selinux_is_active()
{
if [ -z "$SELINUX_ENFORCE" ]; then
selinux_getenforce
fi
case "$SELINUX_ENFORCE" in
Enforcing|Permissive) return 0;;
*) return 1;;
esac
}
selinux_support_is_installed()
{
# This function checks if Plesk SELinux support component is installed
set_selinux_params
[ -s "$selinux_module" ]
}
selinux_configuration_is_required()
{
# All public functions that modify SELinux state should check that this is true!
selinux_is_active && selinux_support_is_installed
}
selinux_get_mount_dir()
{
unset SELINUX_MOUNT_DIR
if awk '$2 == "/selinux"{exit(1)}' /proc/mounts && mkdir -p /selinux; then
SELINUX_MOUNT_DIR=/selinux
else
SELINUX_MOUNT_DIR="`mktemp -d /tmp/selinuxXXXXXX`"
fi >>"$product_log" 2>&1
}
selinux_getenforce()
{
if [ "$1" = "--check" -a -n "$SELINUX_ENFORCE" ]; then
return
fi
unset SELINUX_ENFORCE
if ! ( command -v selinuxenabled >/dev/null 2>&1 && selinuxenabled ); then
SELINUX_ENFORCE=Disabled
return
fi
if awk '$3 == "selinuxfs"{exit(1)}' /proc/mounts; then
selinux_get_mount_dir
mount -t selinuxfs none "$SELINUX_MOUNT_DIR"
fi
if ! command -v getenforce >/dev/null 2>&1; then
SELINUX_ENFORCE=Disabled
return
fi
SELINUX_ENFORCE="`getenforce`"
if test $? -ne 0; then
SELINUX_ENFORCE=Disabled
return
fi
}
selinux_close()
{
if [ -z "$SELINUX_ENFORCE" -o "$SELINUX_ENFORCE" = "Disabled" ]; then
return
fi
setenforce "$SELINUX_ENFORCE"
}
### Copyright 1999-2025. WebPros International GmbH. All rights reserved.
# vim:ft=sh
set_selinux_params()
{
selinux_module="$PRODUCT_ROOT_D/etc/plesk.pp"
}
### Copyright 1999-2025. WebPros International GmbH. All rights reserved.
# vim:ft=sh:
#set_params
set_common_params()
{
common_var=0
PATH=/sbin:/bin:/usr/sbin:/usr/bin:/usr/local/sbin:/usr/local/bin
LANG="`get_default_locale`"
export PATH LANG
unset GREP_OPTIONS
umask 022
ulimit -n 65535 2>/dev/null
get_product_versions
certificate_file="$PRODUCT_ETC_D/httpsd.pem"
services="/etc/services"
crontab="/usr/bin/crontab"
SYSTEM_RC_D="/etc/init.d"
PLESK_LIBEXEC_DIR="/usr/lib/plesk-9.0"
PLESK_DB_DIR="/var/lib/plesk"
PRODUCT_BOOTSTRAPPER_DIR="`printf "/opt/psa/bootstrapper/pp%s-bootstrapper" "$product_this_version"`"
AUTOGENERATED_CONFIGS="#ATTENTION!\n#\n#DO NOT MODIFY THIS FILE BECAUSE IT WAS GENERATED AUTOMATICALLY,\n#SO ALL YOUR CHANGES WILL BE LOST THE NEXT TIME THE FILE IS GENERATED.\n"
AUTOGENERATED_CONFIGS_UPGRADE="#ATTENTION!\n#\n#DO NOT MODIFY THIS FILE BECAUSE IT WAS GENERATED AUTOMATICALLY,\n#SO ALL YOUR CHANGES WILL BE LOST AFTER YOU UPGRADE PLESK.\n"
PRODUCT_LOGS_D="/var/log/plesk"
sendmail="/usr/sbin/sendmail"
ps="ps axw"
ifconfig="/sbin/ifconfig -a"
machine="linux"
if [ -f /etc/debian_version ]; then
linux_distr="debian"
else
linux_distr="redhat"
fi
dummy_home="/"
if [ -x /usr/sbin/nologin ]; then
dummy_shell="/usr/sbin/nologin"
else
dummy_shell="/bin/false"
fi
rp_patch_runtime
}
get_product_versions()
{
# Don't use global variables set elsewhere in this code. Use substitutions if needed.
local prod_root_d="/opt/psa"
product_name="psa"
if [ -z "$product_this_version" ]; then
# 1. Try to fetch version from file created by bootstrapper (should be 3-component).
product_this_version="`cat "/var/lock/plesk-target-version" 2>/dev/null`"
# 2. Fallback to $PRODUCT_ROOT_D/version (should be 3-component).
if [ -z "$product_this_version" -a -r "$prod_root_d/version" ]; then
product_this_version="`awk '{ print $1 }' "$prod_root_d/version"`"
fi
# 3. Fallback to hardcoded version (2-component). This may cause some other code to fail.
if [ -z "$product_this_version" ]; then
product_this_version="18.0"
echo "Unable to determine \$product_this_version, will use less precise value '$product_this_version'" >&2
fi
fi
product_version="$product_this_version"
if [ -z "$product_prev_version" ]; then
if [ -r "$prod_root_d/version.upg" ]; then
product_prev_version=`awk '{ print $1 }' "$prod_root_d/version.upg"`
elif [ -r "$prod_root_d/version" ]; then
product_prev_version=`awk '{ print $1 }' "$prod_root_d/version"`
else
product_prev_version="$product_this_version"
fi
fi
}
# Clean installation of the product is being performed
is_product_installation()
{
[ "X$do_upgrade" != "X1" -a ! -s "/opt/psa/version.upg" ]
}
### Copyright 1999-2025. WebPros International GmbH. All rights reserved.
# vim:syntax=sh
set_nginx_params()
{
nginx_service=nginx
nginx_rc_config="/etc/default/nginx"
nginx_user="nginx"
nginx_bin="/usr/sbin/nginx"
}
nginx_is_rc_enabled()
{
grep -q '^\s*NGINX_ENABLED=\s*"\?yes"\?\s*\(#.*\)\?$' "$nginx_rc_config" >/dev/null 2>&1
}
### Copyright 1999-2025. WebPros International GmbH. All rights reserved.
reexec_with_clean_env "$@"
usage()
{
cat << EOT
Usage: nginx_proxy { --on | --off } --port-map <mapping> [ --no-httpd-selinux-fix ] [ --apache-listen-on <IP> ]
nginx_proxy --switch-apache-ports --port-map <mapping> [ --apache-listen-on <IP> ]
nginx_proxy --status
-s, --status Check whether NGINX is enabled in proxy mode
-e, --on Turn on NGINX as reverse proxy to Apache
-d, --off Turn off NGINX as reverse proxy and make Apache frontend server
--switch-apache-ports
Replace ports and IP address in Apache configuration files
-m, --port-map <from1:to1,from2:to2,...>
Specify Apache ports mapping.
-l, --apache-listen-on <IP>
Specify IP address or '*' for all IPs to bind Apache to.
IPv6 is supported in square brackets form ([xxxx:xxxx:xxxx:xxxx:xxxx:xxxx]).
-n, --no-httpd-selinux-fix
Normally Apache is allowed to bind to a restricted set of ports
by SELinux. By default upon making Apache a backend server
this utility would allow it to bind to any unprivileged port.
This option suppresses such behavior.
You can manually allow Apache to use specific ports, e.g. using:
# semanage port -a -t http_port_t -p tcp <port>
Warning: this utility expects that all web server configuration files except main
ones have already been updated. Otherwise NGINX and Apache may fail to start.
EOT
exit 1
}
# --- args check ---
while [ "$#" -gt 0 ]; do
case "$1" in
-s|--status)
opt_status="yes"
shift
;;
-e|--on)
opt_enable="yes"
shift
;;
-d|--off)
opt_disable="yes"
shift
;;
--switch-apache-ports)
opt_switch_apache_ports="yes"
shift
;;
-m|--port-map)
opt_port_map="$2"
if [ "$#" -ge 2 ]; then shift 2; else usage; fi;
;;
-l|--apache-listen-on)
opt_listen_on="$2"
if [ "$#" -ge 2 ]; then shift 2; else usage; fi;
;;
-n|--no-httpd-selinux-fix)
opt_no_httpd_selinux_fix="yes"
shift
;;
--skip-cleanup)
opt_skip_cleanup="yes"
shift
;;
-h|--help)
usage
;;
*)
echo "Unknown argument '$1'"
echo
usage
;;
esac
done
[ -n "$opt_status" -a -z "$opt_enable$opt_disable$opt_switch_apache_ports$opt_port_map$opt_no_httpd_selinux_fix$opt_listen_on" ] || \
[ -n "$opt_enable" -a -n "$opt_port_map" -a -z "$opt_status$opt_switch_apache_ports" ] || \
[ -n "$opt_disable" -a -n "$opt_port_map" -a -z "$opt_status$opt_switch_apache_ports" ] || \
[ -n "$opt_switch_apache_ports" -a -n "$opt_port_map" -a -z "$opt_status$opt_enable$opt_disable$opt_no_httpd_selinux_fix" ] || \
usage
# --- logging ---
log_transaction_start "nginx_proxy${*:+ $*}" '' 'nginx_proxy.log.XXXXXX'
# --- workers ---
ngxp_enable_rc()
{
local do_enable="$1"
p_echo "Switching NGINX rc enabled state to '$do_enable'"
if grep -q '^\s*NGINX_ENABLED=' "$nginx_rc_config" >/dev/null 2>&1 ; then
sed -e 's/^\(\s*NGINX_ENABLED=\s*\)"\?[^"]*"\?\(\s*\(#.*\)\?\)$/\1'$do_enable'\2/g' "$nginx_rc_config" > "$nginx_rc_config.tmp" && \
mv -f "$nginx_rc_config.tmp" "$nginx_rc_config" || \
rm -f "$nginx_rc_config.tmp"
else
echo "NGINX_ENABLED=$do_enable" >> "$nginx_rc_config"
fi
chmod 644 "$nginx_rc_config"
}
ngxp_find_apache_configs()
{
find $HTTPD_CONF_D $HTTPD_INCLUDE_D -type f \( -name '*.conf' -o -path '*/sites-*' \) | sort | uniq
}
ngxp_switch_apache_ports()
{
local OLD_IFS="$IFS"
local IFS=","
local port_map="$1"
local listen_on="$2"
local from_port to_port sed_cmds
p_echo "Switching Apache ports in config files using mapping '$port_map' and listen_on '$listen_on'"
for port_pair in $port_map ; do
from_port=`get_narg_fs "$port_pair" ':' 1`
to_port=` get_narg_fs "$port_pair" ':' 2`
if [ -z "$listen_on" -o "$listen_on" = '*' ]; then
sed_cmds="$sed_cmds -e "'s/^\(\s*Listen\s\+\)'${from_port}'\>\(.*\)$/\1'${to_port}'\2/g'
sed_cmds="$sed_cmds -e "'s/^\(\s*Listen\s\+\)[^:[:space:]]\+:'${from_port}'\>\(.*\)$/\1'${to_port}'\2/g'
else
sed_cmds="$sed_cmds -e "'s/^\(\s*Listen\s\+\)[^:[:space:]]\+:'${from_port}'\>\(.*\)$/\1'${listen_on}':'${to_port}'\2/g'
sed_cmds="$sed_cmds -e "'s/^\(\s*Listen\s\+\)'${from_port}'\>\(.*\)$/\1'${listen_on}':'${to_port}'\2/g'
fi
if [ -z "$listen_on" ]; then
sed_cmds="$sed_cmds -e "'s/^\(\s*NameVirtualHost\s\+[^:[:space:]]\+\):'${from_port}'\(\s*\(#.*\)\?\)$/\1:'${to_port}'\2/g'
sed_cmds="$sed_cmds -e "'s/^\(\s*<VirtualHost\s\+[^:[:space:]]\+\):'${from_port}'\(\s*>\s*\(#.*\)\?\)$/\1:'${to_port}'\2/g'
else
local to_ip_port="$listen_on:$to_port"
sed_cmds="$sed_cmds -e "'s/^\(\s*NameVirtualHost\s\+\)[^:[:space:]]\+:'${from_port}'\(\s*\(#.*\)\?\)$/\1'${to_ip_port}'\2/g'
sed_cmds="$sed_cmds -e "'s/^\(\s*<VirtualHost\s\+\)[^:[:space:]]\+:'${from_port}'\(\s*>\s*\(#.*\)\?\)$/\1'${to_ip_port}'\2/g'
fi
done
IFS="$OLD_IFS"
ngxp_apache_cfg_bakup_d=`mktemp -d /tmp/nginx_proxy_backups.XXXXXX`
[ "$?" -eq 0 ] || die "Failed to create temporary directory for Apache config backups"
p_echo "Apache config file backups will be saved to '$ngxp_apache_cfg_bakup_d'"
for config in `ngxp_find_apache_configs`; do
grep -q '^[^#]*\(Listen\|NameVirtualHost\|VirtualHost\)' "$config" >/dev/null 2>&1 || continue
mkdir -p "$ngxp_apache_cfg_bakup_d/`dirname $config`"
cp "$config" "$ngxp_apache_cfg_bakup_d/$config"
sed $sed_cmds "$config" > "$config.tmp" && \
! diff -q "$config" "$config.tmp" >/dev/null 2>&1 && \
p_echo "Updating '$config'." && \
mv -f "$config.tmp" "$config" || \
rm -f "$config.tmp"
done
}
ngxp_switch_apache_logformat()
{
local apache_conf_bak="${apache_httpd_conf}.$product_suff"
if ! cp -fp "$apache_httpd_conf" "$apache_conf_bak"; then
p_echo "ngxp_switch_apache_logformat(): cannot backup $apache_httpd_conf. LogFormat not changed"
return 1
fi
p_echo "Fix Apache LogFormat in $apache_httpd_conf"
case "$1" in
proxy-on)
sed -i -e '/^\s*LogFormat/s/%h/%a/g' "$apache_httpd_conf"
;;
proxy-off)
sed -i -e '/^\s*LogFormat/s/%a/%h/g' "$apache_httpd_conf"
;;
*)
rm -f "$apache_conf_bak"
p_echo "ngxp_switch_apache_logformat(): unknown mode $1: should be proxy-on or proxy-off"
return 1
esac
if [ "$?" != "0" ]; then
p_echo "ngxp_switch_apache_logformat(): an error occured when fixing Apache LogFormat. Changes in $apache_httpd_conf are rolled back"
cp -fp "$apache_conf_bak" "$apache_httpd_conf"
return 1
fi
}
ngxp_switch_apache_ports_cleanup()
{
rm -rf "$ngxp_apache_cfg_bakup_d"
}
ngxp_switch_apache_modules()
{
true add_apache_module remove_apache_module
local action="$1"
[ "$action" = "add" -o "$action" = "remove" ] || die "ngxp_switch_apache_modules(): expected 'add' or 'remove' argument"
p_echo "Performing $action of Apache remoteip module"
${action}_apache_module "remoteip"
p_echo "Performing $action of Apache aclr2 module"
${action}_apache_module "aclr"
}
ngxp_switch_selinux_apache_bind_any_port()
{
local enable="$1"
local output
[ "$opt_no_httpd_selinux_fix" = "yes" ] && enable=0
[ "$enable" = "1" -o "$enable" = "0" ] || die "ngxp_switch_selinux_apache_bind_any_port(): expected '0' or '1' argument"
if ! selinux_configuration_is_required; then
p_echo "SELinux adjustments not required (no SELinux support for Plesk or SELinux is disabled)"
return 0
fi
p_echo "Switching Apache ability to bind to any port (SELinux) to $enable"
if ! getsebool -a | grep -q httpd_can_bind_all_ports 2>/dev/null ; then
p_echo "Warning: SELinux boolean httpd_can_bind_all_ports not found. Is plesk.pp policy installed?"
return 1
fi
output=`setsebool -P httpd_can_bind_all_ports $enable 2>&1`
if [ "$?" -ne 0 ]; then
# Policy will often disallow 'setsebool' to append to anything in /tmp/
echo "$output" >>"$product_log"
return 1
fi
}
ngxp_apply_ssl_settings()
{
# N.B.: we don't want to turn on HTTP/2 here, so use sslmng directly
p_echo "Applying custom SSL settings for NGINX"
$PRODUCT_ROOT_D/admin/sbin/sslmng --services "nginx" --set 2>>"$product_log"
}
ngxp_apache_control()
{
local action="$1"
p_echo "Doing Apache $action"
$PRODUCT_ROOT_D/admin/sbin/apache_control_adapter "--$action" 2>>"$product_log"
}
ngxp_nginx_control()
{
local action="$1"
p_echo "Doing NGINX $action"
$PRODUCT_ROOT_D/admin/sbin/nginx_control "--$action" 2>>"$product_log"
}
ngxp_do_status()
{
if nginx_is_rc_enabled ; then
pp_echo "on"
else
pp_echo "off"
fi
}
ngxp_do_enable()
{
nginx_is_rc_enabled && pp_echo "NGINX as reverse proxy is already enabled, but I will reenable it anyway"
add_user_to_group $nginx_user psaserv
ngxp_switch_apache_ports "$opt_port_map" "$opt_listen_on"
ngxp_switch_apache_modules "add"
ngxp_switch_apache_logformat "proxy-on"
ngxp_enable_rc "yes"
ngxp_switch_selinux_apache_bind_any_port 1
ngxp_nginx_control "stop"
ngxp_apply_ssl_settings
ngxp_apache_control "restart" && \
ngxp_nginx_control "start"
register_service "$nginx_service"
ngxp_retval="$?"
}
ngxp_do_disable()
{
nginx_is_rc_enabled || pp_echo "NGINX as reverse proxy is already disabled, but I will redisable it anyway"
ngxp_switch_apache_ports "$opt_port_map" "$opt_listen_on"
ngxp_switch_apache_modules "remove"
ngxp_switch_apache_logformat "proxy-off"
ngxp_enable_rc "no"
ngxp_switch_selinux_apache_bind_any_port 0
unregister_service "$nginx_service"
ngxp_nginx_control "stop" && \
ngxp_apache_control "restart"
ngxp_retval="$?"
del_user_from_group $nginx_user psaserv
}
ngxp_do_opt_switch_apache_ports()
{
ngxp_switch_apache_ports "$opt_port_map" "$opt_listen_on"
}
# --- the script ---
initial_conf
product_default_conf
read_conf
set_common_params
set_apache_params
set_nginx_params
[ "$opt_status" = "yes" ] && ngxp_do_status
[ "$opt_enable" = "yes" ] && ngxp_do_enable
[ "$opt_disable" = "yes" ] && ngxp_do_disable
[ "$opt_switch_apache_ports" = "yes" ] && ngxp_do_opt_switch_apache_ports
if [ "0${ngxp_retval}" -eq 0 ]; then
p_echo "SUCCESS"
[ "$opt_skip_cleanup" = "yes" ] || {
ngxp_switch_apache_ports_cleanup
rm -f "$product_log"
}
fi
exit $ngxp_retval
# vim:ft=sh